Anomaly Detection in Large Scale Networks with Latent Space Models

11/13/2019
by   Wesley Lee, et al.
0

We develop a real-time anomaly detection algorithm for directed activity on large, sparse networks. We model the propensity for future activity using a dynamic logistic model with interaction terms for sender- and receiver-specific latent factors in addition to sender- and receiver-specific popularity scores; deviations from this underlying model constitute potential anomalies. Latent nodal attributes are estimated via a variational Bayesian approach and may change over time, representing natural shifts in network activity. Estimation is augmented with a case-control approximation to take advantage of the sparsity of the network and reduces computational complexity from O(N^2) to O(E), where N is the number of nodes and E is the number of observed edges. We run our algorithm on network event records collected from an enterprise network of over 25,000 computers and are able to identify a red team attack with half the detection rate required of the model without latent interaction terms.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/11/2016

Low Latency Anomaly Detection and Bayesian Network Prediction of Anomaly Likelihood

We develop a supervised machine learning model that detects anomalies in...
research
05/16/2019

Finding Rats in Cats: Detecting Stealthy Attacks using Group Anomaly Detection

Advanced attack campaigns span across multiple stages and stay stealthy ...
research
12/25/2020

Graph Convolutional Networks for traffic anomaly

Event detection has been an important task in transportation, whose task...
research
03/08/2021

ZYELL-NCTU NetTraffic-1.0: A Large-Scale Dataset for Real-World Network Anomaly Detection

Network security has been an active research topic for long. One critica...
research
04/04/2021

Isconna: Streaming Anomaly Detection with Frequency and Patterns

An edge stream is a common form of presentation of dynamic networks. It ...
research
03/11/2021

Bump Hunting in Latent Space

Unsupervised anomaly detection could be crucial in future analyses searc...
research
04/10/2022

Dynamic latent space relational event model

Dynamic relational processes, such as e-mail exchanges, bank loans and s...

Please sign up or login with your details

Forgot password? Click here to reset